Legal
Privacy Policy.
How we collect, use, keep and protect your personal information — in plain language. This policy covers the CCPA and CPRA in California, the state privacy laws that follow them, and the GDPR in Europe.
- Effective
- September 27, 2026
- Updated
- September 27, 2026
- Version
- 1.4
The 30-second version
We collect the minimum needed to sell you AI agents, take payment, support you and improve the products. We do not sell your personal information. We use trusted processors — Stripe, Google, Twilio, ElevenLabs and Anthropic — under contract. You can access, correct, export or delete your data at any time by writing to [email protected].
§ 01
Who we are
This Privacy Policy applies to botlib.ai and every related service (the “Services”), operated by AIBUILDERS LLC, a company registered in the State of Delaware (EIN 35-2843990), with its registered office at 254 Chapman Rd, Ste 208, Newark, DE 19702, United States (“BotLib”, “we”, “us” or “our”). We also keep an office in France: AI BUILDER FRANCE, 60 rue François 1er, 75008 Paris.
BotLib runs a marketplace of AI agents for local businesses. We are the controller of the personal information collected through our site, our sales process, our customer support, and any AI agent we run as a managed service. When you install an agent yourself on your own infrastructure, you are normally the controller of the end-user data that agent processes, and we act as a processor on your instructions.
§ 02
What data do we collect?
What you give us
- Account and contact data — name, email address, phone number, company name, country and job title.
- Payment data — processed and stored by Stripe. We never receive or store your full card number. Stripe may show us limited payment-method and transaction details for billing, support and fraud prevention.
- Communications — messages you send by email, WhatsApp, the contact form or in-product chat.
- The voice assistant on this site — if you start a conversation with the assistant on botlib.ai, your voice is captured and transcribed for the length of that conversation so it can answer you. Nothing is captured until you click to start, and your browser asks your permission for the microphone. The conversation is processed by ElevenLabs. You can ask us to delete it at [email protected].
- Creator data — if you publish on our marketplace: tax identification number, payout details and agent metadata.
What we collect automatically
- Technical logs — page requested, timestamp, IP address, browser or user agent and, where sent, the referring site. They are handled by our host and by Cloudflare to serve and secure the site; no analytics or advertising tool is switched on today.
- Forms and abuse prevention — the IP recorded with a request is truncated; rate limiting uses a short-lived pseudonymous identifier. Turnstile may process technical signals to tell a human from a bot.
- Cookies and local storage — see section 9.
What we receive from others
- Stripe and Calendly — transaction, customer or appointment details needed to bill you and to follow up on your request.
- Communication platforms — whatever you choose to send us when you contact us by email, WhatsApp or LinkedIn.
§ 03
How do we use it?
- To provide the Services — process orders, deliver tutorials, deploy and run the AI agents.
- To bill and take payment — through Stripe; manage subscriptions, refunds and taxes.
- To support you — answer questions, resolve issues and escalate them where needed.
- To improve the products — use support feedback and technical logs to fix errors and add features. We do not train AI models on your data.
- To communicate — service emails, security alerts and, with your consent, product news.
- To comply with the law — tax obligations, creator identity checks and fraud prevention.
- Marketing — only with your consent, and you can unsubscribe at any time.
§ 04
Legal bases (GDPR)
If you are in the European Economic Area, the United Kingdom or Switzerland, we process your personal data on these legal bases:
- Performance of a contract — to provide the Services you bought.
- Legitimate interests — to secure our platform, prevent fraud and improve the products; you may object.
- Consent — for marketing email, non-essential cookies and certain optional analytics.
- Legal obligation — accounting, tax and regulatory reporting.
If you are in the United States, we rely on the disclosures in this policy and on your choices, as the CCPA, the CPRA and the comparable state laws require.
§ 05
Who receives the data?
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it only to these categories of recipient, under their contractual terms and, where applicable, a data processing agreement:
- Stripe, Inc. — payment processing (United States).
- Google LLC — collaboration tools, Google Calendar, YouTube videos embedded in privacy-enhanced mode and, with your consent, Google Analytics (United States / EU).
- Twilio Inc. — SMS and voice telephony (United States).
- ElevenLabs Inc. — conversational voice AI (United States).
- Anthropic PBC — text generation API (United States).
- n8n GmbH — workflow automation (EU).
- Resend — delivery of the email our forms send (United States / EU depending on region).
- Cloudflare, Inc. — DNS, network security, Turnstile anti-spam checks and cookie consent management via Zaraz (United States / EU).
- Rewardful — affiliate tracking, only if that program is switched on (United States).
- GoDaddy, our host — hosting of the site and its database.
- Our professional advisers — lawyers, accountants and auditors bound by professional confidentiality.
- Regulators and law enforcement — only where the law requires it.
- An acquirer or successor — in a merger, acquisition or asset sale, subject to equivalent protections.
§ 06
International transfers
Because we operate in the United States, France, the United Arab Emirates and Thailand, your personal information may be transferred outside the country where you live. When data leaves the European Economic Area, we rely on:
- EU Standard Contractual Clauses where they are built into the relevant provider's terms or agreements.
- The EU–US Data Privacy Framework for certified US processors, where applicable.
- Adequacy decisions adopted by the European Commission, where they exist.
You can ask us for a copy of the safeguards in place.
§ 07
How long do we keep it?
- Account data — for as long as the account is active, then three years after it closes.
- Orders and payment records — ten years for tax and accounting purposes in the United States and the European Union.
- Support messages — three years after your last contact.
- Marketing consent records — three years after consent is withdrawn.
- AI agent conversation logs — kept for the life of the subscription, so that a customer can find a conversation again later. You can ask us to delete them at any time, or to set a shorter retention period.
- Cookies — see section 9.
Once those periods expire, we delete or anonymize the data.
§ 08
Your rights
Depending on where you live, you have the following rights:
California residents (CCPA / CPRA)
- The right to know what personal information we collect, use and disclose.
- The right to request deletion of your personal information.
- The right to correct inaccurate information.
- The right to opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information for cross-context behavioral advertising.
- The right to limit the use of sensitive personal information; we do not use it for purposes that require this.
- The right not to be discriminated against for exercising your rights.
Residents of other US states with comparable privacy laws — including Colorado, Connecticut, Virginia, Texas, Oregon and Utah — have equivalent rights, and we handle their requests the same way.
Everyone else, where applicable
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete.
- Erasure — ask us to delete your data, also called the “right to be forgotten”.
- Restriction — limit our use of your data while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests, or to direct marketing.
- Withdrawal of consent — at any time, without affecting processing already carried out.
To exercise a right, write to [email protected] with the subject line “Privacy request”. We respond within 30 days, or within the period the applicable law sets. To protect your data, we may ask you to verify your identity. You may use an authorized agent where state law allows it.
If you believe your request was not handled properly, you can complain to your data protection authority — the CNIL in France (cnil.fr), the ICO in the United Kingdom, or your state attorney general in the United States.
§ 10
AI agents: what applies specifically
Our agents — Atlas, Echo, Rhea, Nova and Orion — process data on behalf of the businesses that deploy them. Please read this section carefully.
What an agent may process
- Voice recordings and call transcripts for Atlas.
- Texts, emails and forms sent by end users.
- Phone numbers, names and appointment times.
- Conversation history within a single session.
How we protect it
- We do not use end-user conversations to train AI models, ours or anyone else's.
- Voice and text data sent to ElevenLabs and Anthropic is handled according to the plan, the retention settings and the terms that apply to the customer's service. The configuration chosen is documented at deployment.
- Conversation logs are kept for the life of the subscription: a customer may need to find a call again months later. They are deleted on request — the customer's, or an end user's exercising their right to erasure.
- The customer must tell end users — the people calling Atlas, for instance — that they are speaking with an AI assistant and, where recording is enabled, obtain or give whatever notice the applicable law requires. In the United States this includes state two-party consent rules.
§ 11
How do we protect data?
- All data in transit is encrypted with TLS 1.2 or later.
- Production secrets stay out of the source code, in server configuration or in the providers' credential managers, with restricted access.
- Access is limited to authorized people who need it for their work.
- We review the security of our infrastructure and our processors regularly.
- The admin dashboard is protected by a signed session, a persistent rate limit and a bot check in production.
No system is invulnerable. In the unlikely event of a breach affecting your data, we will notify you and the competent authorities within 72 hours where the GDPR requires it, and without unreasonable delay under US state breach notification laws.
§ 12
Minors
Our Services are neither intended for nor directed at people under 16. We do not knowingly collect personal information about anyone under 16. If you believe a minor has given us personal information, contact us and we will delete it.
§ 13
Changes to this policy
We may change this Privacy Policy. When we do, we update the “Updated” date at the top of the page. If the changes are material, we will tell you by email or through a visible notice on the site at least 30 days before they take effect.
The version in force always replaces earlier ones. You can ask us by email for a copy of a previous version.
§ 14
Contact and data protection
For any question, complaint or request about your rights and the protection of your data, contact us:
- Controller
- AIBUILDERS LLC
- Registered office
- 254 Chapman Rd, Ste 208
Newark, DE 19702, United States - France office
- AI BUILDER FRANCE
60 rue François 1er
75008 Paris, France
AI Ambassador for the French OSEZ IA programme - [email protected]
- Phone (US)
- +1 302 947 8583
- +33 6 81 15 04 70
For European Union matters, you may also complain to the data protection authority where you live. The European Data Protection Board keeps a list at edpb.europa.eu.